Amazon AWS AI Practitioner AIF-C01 AI Governance Compliance Services And Data Lifecycle Practice Test
This AWS Certified AI Practitioner AIF-C01 practice test focuses on ai governance compliance services and data lifecycle through original scenario-based questions aligned to AWS Exam Guide version 1.1 published April 30, 2026. Use the full ExamSnap AIF-C01 collection for broader practice across all five current exam domains. For broader exam preparation, review the Amazon AWS Certified AI Practitioner AIF-C01 Exam Dumps page.
Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.
Nod Publishers is moving a fraud-review pilot from pilot to production. The key decision is how to identify supported software vulnerabilities and exposure findings in AWS workloads. Which option is the strongest fit if the team wants to limit exposure of sensitive data? The team will document the rationale for auditors and wants the recommendation to be defensible from the scenario facts. The control owner requires evidence from 5 test groups before the 195-day release review.
Correct answer: E
Why: Amazon Inspector provides automated vulnerability management for supported compute and container resources. It directly addresses the requirement in this scenario.
Option review:
A: Trusted Advisor provides checks that can support governance and operational improvement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: Macie helps identify sensitive data in S3 and can support data-protection governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Amazon Inspector provides automated vulnerability management for supported compute and container resources. It directly addresses the requirement in this scenario.
Learning point: Amazon Inspector – Amazon Inspector provides automated vulnerability management for supported compute and container resources.
A workshop at Fabrikam Health focuses on a single decision: how to observe system health, model/application behavior, security signals, and policy compliance over time. Which option should the AI product manager recommend? The team wants the least complex technically correct choice that satisfies the requirement. The project has 2 downstream consumers and a monthly review of approximately 232 sampled interactions.
Correct answer: A
Why: Governance is ongoing rather than a one-time launch activity. It directly addresses the requirement in this scenario.
Option review:
A: Governance is ongoing rather than a one-time launch activity. It directly addresses the requirement in this scenario.
B: Governance effort should scale with potential harm, autonomy, sensitivity, and business impact. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: Policies establish organization-wide expectations and decision rights. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: Continuous monitoring – Governance is ongoing rather than a one-time launch activity.
For the compliance-assistant prototype at Wingtip Logistics, stakeholders need to classify the GenAI use case by the organization level of ownership/control and use that scope to guide security priorities. Which concept, service, or technique most directly addresses this goal? The workload has passed basic feasibility checks, so the remaining question is which approach best matches the requirement. The rollout spans 7 application teams, each using the same approved requirement set for the next 269 days.
Correct answer: B
Why: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. It directly addresses the requirement in this scenario.
Option review:
A: Governance depends on people recognizing and following the controls, not only on technical enforcement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. It directly addresses the requirement in this scenario.
C: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: Transparency requirements create consistent disclosure and documentation expectations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: Generative AI Security Scoping Matrix – The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines.
Trey Research is comparing alternatives for its forecasting initiative. The AI product manager needs to record AWS API activity for auditing, investigation, and governance. Which option is most appropriate while trying to keep the design easy to explain? Stakeholders have ruled out a broad redesign and want the choice that most precisely addresses the stated need. The evaluation set contains examples from 4 business workflows and 306 recent production cases.
Correct answer: C
Why: CloudTrail captures account activity and API events across supported services. It directly addresses the requirement in this scenario.
Option review:
A: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: IAM roles, policies, and permissions are core controls for least-privilege access. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: CloudTrail captures account activity and API events across supported services. It directly addresses the requirement in this scenario.
D: AgentCore Identity integrates identity and authorization into agent workflows. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Trusted Advisor provides checks that can support governance and operational improvement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: AWS CloudTrail – CloudTrail captures account activity and API events across supported services.
An architecture review at Bellows College has narrowed a customer-support modernization decision to one requirement: keep regulated data and processing in approved geographic locations when required. What should the operations manager select? Operational ownership is already assigned, so the team is comparing technical fit rather than staffing models. The initial rollout covers 343 internal users across 9 business units.
Correct answer: D
Why: Residency requirements can constrain region, service, replication, and backup choices. It directly addresses the requirement in this scenario.
Option review:
A: Governance effort should scale with potential harm, autonomy, sensitivity, and business impact. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: Residency requirements can constrain region, service, replication, and backup choices. It directly addresses the requirement in this scenario.
E: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: Data residency control – Residency requirements can constrain region, service, replication, and backup choices.
The AI product manager at Blue Yonder Airlines is preparing a recommendation for a agentic workflow trial. The recommendation must apply stronger approval and testing to high-impact AI uses than to low-risk internal experiments. Which choice is the best match? Existing application interfaces can accommodate any of the listed choices, so functional fit is the deciding factor. The workload processes about 380 requests during its busiest hour and has a documented fallback path.
Correct answer: E
Why: Governance effort should scale with potential harm, autonomy, sensitivity, and business impact. It directly addresses the requirement in this scenario.
Option review:
A: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: Transparency requirements create consistent disclosure and documentation expectations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Governance effort should scale with potential harm, autonomy, sensitivity, and business impact. It directly addresses the requirement in this scenario.
Learning point: Risk-based review strategy – Governance effort should scale with potential harm, autonomy, sensitivity, and business impact.
Woodgrove Bank has completed discovery for a contact-center transformation. Before implementation, the operations manager must decide how to review supported best-practice checks and recommendations across categories such as security, resilience, performance, and cost. Which choice best satisfies that requirement? Assume the required AWS capabilities are available in the selected Region and normal governance controls are in place. The pilot uses 417 representative records from 3 approved data sources.
Correct answer: A
Why: Trusted Advisor provides checks that can support governance and operational improvement. It directly addresses the requirement in this scenario.
Option review:
A: Trusted Advisor provides checks that can support governance and operational improvement. It directly addresses the requirement in this scenario.
B: AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: AWS Artifact provides on-demand access to AWS security and compliance documents. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Encryption reduces unauthorized disclosure risk when combined with proper key and access management. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: AWS Trusted Advisor – Trusted Advisor provides checks that can support governance and operational improvement.
While planning a operations automation program, Wide World Importers identifies this requirement: keep data and logs only for the period required by business, legal, or regulatory needs. Which option should the AI product manager prioritize if the goal is to control recurring cost? The review committee wants a direct mapping from the requirement to the chosen capability. The first release supports 8 departments and is reviewed every 454 days.
Correct answer: B
Why: Retention limits reduce risk and support records-management obligations. It directly addresses the requirement in this scenario.
Option review:
A: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: Retention limits reduce risk and support records-management obligations. It directly addresses the requirement in this scenario.
C: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: Residency requirements can constrain region, service, replication, and backup choices. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: Retention policy – Retention limits reduce risk and support records-management obligations.
A proof of concept at VanArsdel Media exposed a design decision for the operations manager: the solution must ensure developers, reviewers, support staff, and business owners understand AI risks, controls, and escalation procedures. Which option most directly solves that problem? The solution will serve multiple internal teams, so the recommendation should be reusable without changing the core requirement. The service has a 491-millisecond internal response target for the affected workflow.
Correct answer: C
Why: Governance depends on people recognizing and following the controls, not only on technical enforcement. It directly addresses the requirement in this scenario.
Option review:
A: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: Governance depends on people recognizing and following the controls, not only on technical enforcement. It directly addresses the requirement in this scenario.
D: Residency requirements can constrain region, service, replication, and backup choices. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: Team training – Governance depends on people recognizing and following the controls, not only on technical enforcement.
Datum Dynamics is documenting the target state for a internal search upgrade. The AI product manager needs a solution that can record and evaluate resource configurations against rules to support governance and compliance monitoring. Which option is the strongest fit? The decision must follow the workload characteristics rather than a preference for the largest model or newest service. The team is comparing 2 candidate designs after a 528-day proof of concept.
Correct answer: D
Why: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. It directly addresses the requirement in this scenario.
Option review:
A: Macie helps identify sensitive data in S3 and can support data-protection governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: Bedrock Guardrails can help enforce content and data-safety policies around supported model calls. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: AWS Artifact provides on-demand access to AWS security and compliance documents. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. It directly addresses the requirement in this scenario.
E: AgentCore Identity integrates identity and authorization into agent workflows. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: AWS Config – AWS Config tracks configuration state and can evaluate resources for compliance with defined rules.
Alpine Ski House is reviewing a document-intelligence project. The operations manager has one primary requirement: define how data is created, classified, used, archived, and deleted across the AI system. Which choice best fits the requirement? The security baseline is already defined; the decision here concerns the specific capability described in the requirement. The control owner requires evidence from 7 test groups before the 565-day release review.
Correct answer: E
Why: Lifecycle governance ensures data is managed consistently from acquisition through disposal. It directly addresses the requirement in this scenario.
Option review:
A: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: Policies establish organization-wide expectations and decision rights. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: AI systems and threats evolve, so governance must be revisited. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Lifecycle governance ensures data is managed consistently from acquisition through disposal. It directly addresses the requirement in this scenario.
Learning point: Data lifecycle policy – Lifecycle governance ensures data is managed consistently from acquisition through disposal.
During a design review for Humongous Insurance, the AI product manager must define approved uses, prohibited uses, data handling, oversight, and accountability before broad AI adoption. The team also wants to use current managed AWS capabilities. What should the team choose? The recommendation must solve the stated requirement without introducing unrelated platform complexity. The project has 4 downstream consumers and a monthly review of approximately 602 sampled interactions.
Correct answer: A
Why: Policies establish organization-wide expectations and decision rights. It directly addresses the requirement in this scenario.
Option review:
A: Policies establish organization-wide expectations and decision rights. It directly addresses the requirement in this scenario.
B: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: Transparency requirements create consistent disclosure and documentation expectations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: AI systems and threats evolve, so governance must be revisited. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: Written AI policy – Policies establish organization-wide expectations and decision rights.
Graphic Design Institute is moving a claims-processing redesign from pilot to production. The key decision is how to obtain AWS compliance reports and agreements relevant to audit and assurance work. Which option is the strongest fit if the team wants to limit exposure of sensitive data? The design must remain supportable after launch, but no additional feature is required beyond the stated need. The rollout spans 9 application teams, each using the same approved requirement set for the next 639 days.
Correct answer: B
Why: AWS Artifact provides on-demand access to AWS security and compliance documents. It directly addresses the requirement in this scenario.
Option review:
A: Trusted Advisor provides checks that can support governance and operational improvement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: AWS Artifact provides on-demand access to AWS security and compliance documents. It directly addresses the requirement in this scenario.
C: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: Encryption reduces unauthorized disclosure risk when combined with proper key and access management. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: IAM roles, policies, and permissions are core controls for least-privilege access. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: AWS Artifact – AWS Artifact provides on-demand access to AWS security and compliance documents.
A workshop at Relecloud focuses on a single decision: how to collect metrics, logs, and traces that make AI application behavior understandable and diagnosable. Which option should the AI product manager recommend? A short pilot window means the team prefers an approach that can be evaluated with clear success criteria. The evaluation set contains examples from 6 business workflows and 676 recent production cases.
Correct answer: C
Why: Observability supports operations, audit, and incident response. It directly addresses the requirement in this scenario.
Option review:
A: Governance effort should scale with potential harm, autonomy, sensitivity, and business impact. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: Policies establish organization-wide expectations and decision rights. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: Observability supports operations, audit, and incident response. It directly addresses the requirement in this scenario.
D: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Transparency requirements create consistent disclosure and documentation expectations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: Observability – Observability supports operations, audit, and incident response.
For the developer-productivity pilot at Adventure Works Manufacturing, stakeholders need to define what users, reviewers, and auditors must be told about AI use, limitations, sources, and decision impact. Which concept, service, or technique most directly addresses this goal? The architecture board will reject a choice that addresses a different problem from the one described. The initial rollout covers 713 internal users across 3 business units.
Correct answer: D
Why: Transparency requirements create consistent disclosure and documentation expectations. It directly addresses the requirement in this scenario.
Option review:
A: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: Transparency requirements create consistent disclosure and documentation expectations. It directly addresses the requirement in this scenario.
E: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: Transparency standard – Transparency requirements create consistent disclosure and documentation expectations.
Proseware Services is comparing alternatives for its fraud-review pilot. The AI product manager needs to identify supported software vulnerabilities and exposure findings in AWS workloads. Which option is most appropriate while trying to keep the design easy to explain? Budget has been approved for the project, but the team still wants to avoid unnecessary recurring consumption. The workload processes about 750 requests during its busiest hour and has a documented fallback path.
Correct answer: E
Why: Amazon Inspector provides automated vulnerability management for supported compute and container resources. It directly addresses the requirement in this scenario.
Option review:
A: AgentCore Identity integrates identity and authorization into agent workflows. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: CloudTrail captures account activity and API events across supported services. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: Macie helps identify sensitive data in S3 and can support data-protection governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: PrivateLink provides private connectivity to supported AWS services and endpoints. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Amazon Inspector provides automated vulnerability management for supported compute and container resources. It directly addresses the requirement in this scenario.
Learning point: Amazon Inspector – Amazon Inspector provides automated vulnerability management for supported compute and container resources.
An architecture review at Lucerne Publishing has narrowed a analytics modernization decision to one requirement: define which AI interactions, tool actions, security events, and administrative changes must be recorded. What should the operations manager select? The team will validate the result with representative production examples before rollout. The pilot uses 787 representative records from 5 approved data sources.
Correct answer: A
Why: Logging requirements should be intentional and balanced with privacy and retention needs. It directly addresses the requirement in this scenario.
Option review:
A: Logging requirements should be intentional and balanced with privacy and retention needs. It directly addresses the requirement in this scenario.
B: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: Policies establish organization-wide expectations and decision rights. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: Logging policy – Logging requirements should be intentional and balanced with privacy and retention needs.
The AI product manager at Lamna Healthcare is preparing a recommendation for a compliance-assistant prototype. The recommendation must reassess models, prompts, data, controls, vendors, and risk on a defined schedule and after material change. Which choice is the best match? The pilot has representative data, and the team will measure the selected approach against an agreed acceptance threshold. The first release supports 2 departments and is reviewed every 824 days.
Correct answer: B
Why: AI systems and threats evolve, so governance must be revisited. It directly addresses the requirement in this scenario.
Option review:
A: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: AI systems and threats evolve, so governance must be revisited. It directly addresses the requirement in this scenario.
C: Governance effort should scale with potential harm, autonomy, sensitivity, and business impact. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Governance depends on people recognizing and following the controls, not only on technical enforcement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: Regular review cadence – AI systems and threats evolve, so governance must be revisited.
Contoso Retail has completed discovery for a forecasting initiative. Before implementation, the operations manager must decide how to review supported best-practice checks and recommendations across categories such as security, resilience, performance, and cost. Which choice best satisfies that requirement? The team will document the rationale for auditors and wants the recommendation to be defensible from the scenario facts. The service has a 861-millisecond internal response target for the affected workflow.
Correct answer: C
Why: Trusted Advisor provides checks that can support governance and operational improvement. It directly addresses the requirement in this scenario.
Option review:
A: Macie helps identify sensitive data in S3 and can support data-protection governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: IAM roles, policies, and permissions are core controls for least-privilege access. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: Trusted Advisor provides checks that can support governance and operational improvement. It directly addresses the requirement in this scenario.
D: AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Amazon Inspector provides automated vulnerability management for supported compute and container resources. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: AWS Trusted Advisor – Trusted Advisor provides checks that can support governance and operational improvement.
While planning a customer-support modernization, Fourth Coffee identifies this requirement: observe system health, model/application behavior, security signals, and policy compliance over time. Which option should the AI product manager prioritize if the goal is to control recurring cost? The team wants the least complex technically correct choice that satisfies the requirement. The team is comparing 4 candidate designs after a 898-day proof of concept.
Correct answer: D
Why: Governance is ongoing rather than a one-time launch activity. It directly addresses the requirement in this scenario.
Option review:
A: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: Governance depends on people recognizing and following the controls, not only on technical enforcement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: Governance is ongoing rather than a one-time launch activity. It directly addresses the requirement in this scenario.
E: AI systems and threats evolve, so governance must be revisited. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: Continuous monitoring – Governance is ongoing rather than a one-time launch activity.
A proof of concept at Margie Travel exposed a design decision for the operations manager: the solution must classify the GenAI use case by the organization level of ownership/control and use that scope to guide security priorities. Which option most directly solves that problem? The workload has passed basic feasibility checks, so the remaining question is which approach best matches the requirement. The control owner requires evidence from 9 test groups before the 935-day release review.
Correct answer: E
Why: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. It directly addresses the requirement in this scenario.
Option review:
A: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: AI systems and threats evolve, so governance must be revisited. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: Governance depends on people recognizing and following the controls, not only on technical enforcement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. It directly addresses the requirement in this scenario.
Learning point: Generative AI Security Scoping Matrix – The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines.
School of Fine Art is documenting the target state for a contact-center transformation. The AI product manager needs a solution that can obtain AWS compliance reports and agreements relevant to audit and assurance work. Which option is the strongest fit? Stakeholders have ruled out a broad redesign and want the choice that most precisely addresses the stated need. The project has 6 downstream consumers and a monthly review of approximately 972 sampled interactions.
Correct answer: A
Why: AWS Artifact provides on-demand access to AWS security and compliance documents. It directly addresses the requirement in this scenario.
Option review:
A: AWS Artifact provides on-demand access to AWS security and compliance documents. It directly addresses the requirement in this scenario.
B: AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: PrivateLink provides private connectivity to supported AWS services and endpoints. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: AWS Artifact – AWS Artifact provides on-demand access to AWS security and compliance documents.
Northwind Analytics is reviewing a operations automation program. The operations manager has one primary requirement: collect metrics, logs, and traces that make AI application behavior understandable and diagnosable. Which choice best fits the requirement? Operational ownership is already assigned, so the team is comparing technical fit rather than staffing models. The rollout spans 3 application teams, each using the same approved requirement set for the next 49 days.
Correct answer: B
Why: Observability supports operations, audit, and incident response. It directly addresses the requirement in this scenario.
Option review:
A: Transparency requirements create consistent disclosure and documentation expectations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: Observability supports operations, audit, and incident response. It directly addresses the requirement in this scenario.
C: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: Policies establish organization-wide expectations and decision rights. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: Observability – Observability supports operations, audit, and incident response.
During a design review for Litware Financial, the AI product manager must define what users, reviewers, and auditors must be told about AI use, limitations, sources, and decision impact. The team also wants to use current managed AWS capabilities. What should the team choose? Existing application interfaces can accommodate any of the listed choices, so functional fit is the deciding factor. The evaluation set contains examples from 8 business workflows and 86 recent production cases.
Correct answer: C
Why: Transparency requirements create consistent disclosure and documentation expectations. It directly addresses the requirement in this scenario.
Option review:
A: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: Transparency requirements create consistent disclosure and documentation expectations. It directly addresses the requirement in this scenario.
D: Governance depends on people recognizing and following the controls, not only on technical enforcement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: Transparency standard – Transparency requirements create consistent disclosure and documentation expectations.
Correct answer: D
Why: CloudTrail captures account activity and API events across supported services. It directly addresses the requirement in this scenario.
Option review:
A: Amazon Inspector provides automated vulnerability management for supported compute and container resources. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: AWS Artifact provides on-demand access to AWS security and compliance documents. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: Encryption reduces unauthorized disclosure risk when combined with proper key and access management. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: CloudTrail captures account activity and API events across supported services. It directly addresses the requirement in this scenario.
E: Trusted Advisor provides checks that can support governance and operational improvement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
Learning point: AWS CloudTrail – CloudTrail captures account activity and API events across supported services.
A workshop at Coho Winery focuses on a single decision: how to define which AI interactions, tool actions, security events, and administrative changes must be recorded. Which option should the AI product manager recommend? The review committee wants a direct mapping from the requirement to the chosen capability. The workload processes about 160 requests during its busiest hour and has a documented fallback path.
Correct answer: E
Why: Logging requirements should be intentional and balanced with privacy and retention needs. It directly addresses the requirement in this scenario.
Option review:
A: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
B: Residency requirements can constrain region, service, replication, and backup choices. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
C: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
D: Governance depends on people recognizing and following the controls, not only on technical enforcement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.
E: Logging requirements should be intentional and balanced with privacy and retention needs. It directly addresses the requirement in this scenario.
Learning point: Logging policy – Logging requirements should be intentional and balanced with privacy and retention needs.
Popular posts
Recent Posts
